This Data Processing Addendum (this “DPA”) is incorporated into and forms part of the Terms of Service (together with any SOWs, the “Agreement”) between The Langston Co. (“Langston”)and the legal entity that has accepted the Agreement (“Client”).
Capitalized terms used in this DPA shall have the meanings set forth in this DPA. Capitalized terms used but not otherwise defined herein shall have the meanings given to them in the Agreement. Except as expressly modified below, the terms of the Agreement shall remain in full force and effect.
The parties hereby agree that the terms and conditions set out below shall be added as an addendum to the Agreement. The following obligations shall only apply to the extent required by Data Protection Laws with regard to the relevant Client Personal Data, if applicable.
1.1 “Controller” means an entity that determines the purposes and means of the Processing of Personal Data.
1.2 “Client Personal Data” means Personal Data within Client Materials or Survey Data pertaining to Client Sourced Research Participants that Langston Processes on behalf of Client to perform the Services under the Agreement. For avoidance of doubt, “Client Personal Data” does not include Usage Data or Survey Data pertaining to Langston Sourced Research Participants.
1.3 “Data Protection Laws” means the data privacy and security laws and regulations of any jurisdiction applicable to the Processing of Client Personal Data, including, in each case to the extent applicable, European Data Protection Laws and the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020, and its implementing regulations (collectively, “CCPA”).
1.4 “Data Subject” means the identified or identifiable natural person who is the subject of Personal Data.
1.5 “European Data Protection Laws” means, in each case to the extent applicable: (a) the EU General Data Protection Regulation 2016/679 (“GDPR”); (b) the GDPR as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018 (“UK GDPR”), the Data Protection Act of 2018, and all other laws relating to data protection, the processing of personal data, privacy, or electronic communications in force from time to time in the United Kingdom (collectively, “UK Data Protection Laws”); (c) the Swiss Federal Act on Data Protection (“Swiss FADP”); and (d) any other applicable law, rule, or regulation related to the protection of Client Personal Data in the European Economic Area, United Kingdom, or Switzerland that is already in force or that will come into force during the term of this DPA.
1.6 “Personal Data” means information that constitutes “personal information,” “personal data,” “personally identifiable information,” or similar term under Data Protection Laws.
1.7 “Process” means any operation or set of operations performed upon Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, alignment, combination, restriction, erasure, destruction or disclosure by transmission, dissemination or otherwise making available.
1.8 “Processor” means an entity that Processes Personal Data on behalf of a Controller.
1.9 Security Incident” means a breach of Langston’s security that leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Client Personal Data in Langston’s possession, custody, or control. “Security Incident” does not include unsuccessful attempts or activities that do not compromise the security of Client Personal Data, including unsuccessful log-in attempts, pings, port scans, denial of service attacks, or other network attacks on firewalls or networked systems.
1.10 “Services” means the services that Langston has agreed to provide to Client under the Agreement.
1.11 “Standard Contractual Clauses” means, as applicable, Module Two (Transfer controller to processor) or Module Three (Transfer processor to processor) of the standard contractual clauses approved by Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council (currently available at: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32021D0914&qid=1688587744942), as supplemented or modified by Appendix 3.
1.12 “Subprocessor” means any Processor appointed by Langston to Process Client Personal Data on behalf of Client under the Agreement.
1.13 “Supervisory Authority” means an independent competent public authority established or recognized under Data Protection Laws.
2.1 Roles of the Parties; Compliance. The parties acknowledge and agree that, as between the parties, with regard to the Processing of Client Personal Data under the Agreement, Client is a Controller and Langston is a Processor. In some circumstances, the parties acknowledge that Client may be acting as a Processor to a third-party Controller in respect of Client Personal Data, in which case Langston will remain a Processor with respect to the Client in such event. Each party will comply with the obligations applicable to it in such role under Data Protection Laws with respect to the Processing of Client Personal Data.
2.2 Client Instructions. Langston will Process Client Personal Data only in accordance with Client’s documented instructions unless otherwise required by applicable law, in which case Langston will inform Client of such Processing unless notification is prohibited by applicable law. Client hereby instructs Langston to Process Client Personal Data: (a) to provide the Services to Client; (b) to perform its obligations and exercise its rights under the Agreement and this DPA; and (c) as necessary to prevent or address technical problems with the Services. Langston will notify Client if, in its opinion, an instruction of Client infringes upon Data Protection Laws. Client’s instructions for the Processing of Client Personal Data shall comply with Data Protection Laws. Client shall be responsible for: (i) giving adequate notice and making all appropriate disclosures to Data Subjects regarding Client’s use and disclosure and Langston’s Processing of Client Personal Data; and (ii) obtaining all necessary rights, and, where applicable, all appropriate and valid consents to disclose such Client Personal Data to Langston to permit the Processing of such Client Personal Data by Langston for the purposes of performing Langston’s obligations under the Agreement or as may be required by Data Protection Laws. Client shall notify Langston of any changes in, or revocation of, the permission to use, disclose, or otherwise Process Client Personal Data that would impact Langston’s ability to comply with the Agreement, this DPA, or Data Protection Laws.
2.3 Details of Processing.The parties acknowledge and agree that the nature and purpose of the Processing of Client Personal Data, the types of Client Personal Data Processed, the categories of Data Subjects, and other details regarding the Processing of Client Personal Data are as set forth in Appendix 1.
2.4 Processing Subject to the CCPA. As used in this Section 2.4, the terms “Sell,” “Share,” “Business Purpose,” and “Commercial Purpose” shall have the meanings given in the CCPA and “Personal Information” shall mean any personal information (as defined in the CCPA) contained in Client Personal Data. Langston will not: (a) Sell or Share any Personal Information; (b) retain, use, or disclose any Personal Information (i) for any purpose other than for the Business Purposes specified in the Agreement, including for any Commercial Purpose other than the Business Purposes specified in the Agreement, or as otherwise permitted by the CCPA, or (ii) outside of the direct business relationship between Client and Langston; or (c) combine Personal Information received from, or on behalf of, Client with Personal Data received from or on behalf of any third party, or collected from Langston’s own interaction with Data Subjects, except to perform any Business Purpose permitted by the CCPA. Langston hereby certifies that it understands the foregoing restrictions under this Section 2.4. and will comply with them. The parties acknowledge that the Personal Information disclosed by Client to Langston is provided to Langston only for the limited and specified purposes set forth in Appendix 1. Langston will comply with applicable obligations under the CCPA and provide the same level of privacy protection to Personal Information as is required by the CCPA. Client has the right to take reasonable and appropriate steps to help ensure that Company uses the Personal Information transferred in a manner consistent with Client’s obligations under the CCPA by exercising Client’s audit rights in Section 8. Langston will notify Client if it makes a determination that Langston can no longer meet its obligations under the CCPA. If Langston notifies Client of unauthorized use of Personal Information, including under the foregoing sentence, Client will have the right to take reasonable and appropriate steps to stop and remediate such unauthorized use by limiting the Personal Information shared with Langston, terminating the portion of the Agreement relevant to such unauthorized use, or such other steps mutually agreed between the parties in writing.
2.5 De-identified Data. With respect to any de-identified data created by Langston from Client Personal Data, Langston will: (i) take any necessary measures to ensure that such de-identified data cannot be associated with a Data Subject; (ii) publicly commit to maintaining and using de-identified data without attempting to re-identify the data; (iii) comply with the requirements of Data Protection Laws with respect to the creation of such de-identified data; and (iv) contractually obligate any recipients of the de-identified data to comply with restrictions substantially similar to those set forth in this Section 2.5.
Langston shall take reasonable steps to ensure that Langston personnel who Process Client Personal Data are subject to obligations of confidentiality or are under an appropriate statutory obligation of confidentiality with respect to such Client Personal Data.
4.1 Security Measures. Taking into account the state of the art, the costs of implementation and the nature, scope, context, and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Langston shall implement appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk, in accordance with the security standards in Appendix 2 (the “Security Measures”). Client acknowledges that the Security Measures may be updated from time to time upon reasonable notice to Client to reflect process improvements or changing practices, provided that the modifications will not materially decrease Langston’s security obligations hereunder.
4.2 Security Incidents. Upon becoming aware of a confirmed Security Incident, Langston will: (a) notify Client of the Security Incident without undue delay after becoming aware of the Security Incident; and (b) take reasonable steps to identify the cause of such Security Incident, minimize harm, and prevent a recurrence. Langston will take reasonable steps to provide Client with information available to Langston that Client may reasonably require to comply with its obligations under Data Protection Laws. Langston’s notification of or response to a Security Incident under this Section 1.1 will not be construed as an acknowledgement by Langston of any fault or liability with respect to the Security Incident.
4.3 Client Responsibilities. Client agrees that, without limitation of Langston’s obligations under this Section 4, Client is solely responsible for its use of the Services, including: (a) making appropriate use of the Services to ensure a level of security appropriate to the risk in respect of the Client Personal Data; and (b) securing any account authentication credentials, systems, and devices Client uses to access or connect to the Services, where applicable. Without limiting Langston’s obligations hereunder, Client is responsible for reviewing the information made available by Langston relating to data security and making an independent determination as to whether the Services meet Client’s requirements and legal obligations under Data Protection Laws.
Subject to the requirements of this Section 5, Client generally authorizes Langston to engage Subprocessors as Langston considers reasonably appropriate for the Processing of Client Personal Data. A list of Langston’s Subprocessors, including their functions and locations, is available upon Client’s request and may be updated by Langston from time to time in accordance with this Section 5. Langston will notify Client of the addition or replacement of any Subprocessor at least ten (10) days prior to such engagement. Client may object to such changes on reasonable data protection grounds by providing Langston written notice of such objection within ten (10) days. Upon receiving such an objection, where practicable and at Langston’s sole discretion Langston will use commercially reasonable efforts to: (a) work with Client in good faith to make available a commercially reasonable change in the provision of the Services which avoids the use of that proposed Subprocessor; or (b) take corrective steps requested by Client in its objection and proceed to use the new Subprocessor. If Langston informs Client that such change or corrective steps cannot be made, Client may, as its sole and exclusive remedy available under this Section 5, terminate the relevant portion of the Agreement involving the Services which require the use of the proposed Subprocessor by providing written notice to Langston. When engaging any Subprocessor, Langston will enter into a written contract with such Subprocessor containing data protection obligations not less protective than those in this DPA. Langston shall be liable for the acts and omissions of the Subprocessor to the extent Langston would be liable under the Agreement and this DPA.
Langston will, taking into account the nature of the Processing of Client Personal Data and the functionality of the Services, provide reasonable assistance to Client by appropriate technical and organizational measures, insofar as this is possible, as necessary for Client to fulfill its obligations under Data Protection Laws to respond to requests by Data Subjects to exercise their rights under Data Protection Laws. Langston reserves the right to charge Client on a time and materials basis in the event that Langston considers that such assistance is onerous, complex, frequent, or time consuming. If Langston receives a request from a Data Subject under any Data Protection Laws with respect to Client Personal Data, Langston will advise the Data Subject to submit the request to Client and Client will be responsible for responding to any such request.
In the event that Data Protection Laws require Client to conduct a data protection impact assessment, transfer impact assessment, or prior consultation with a Supervisory Authority in connection with Langston’s Processing of Client Personal Data, following written request from Client, Langston shall use reasonable commercial efforts to provide relevant information and assistance to Client to fulfil such request, taking into account the nature of Langston’s Processing of Client Personal Data and the information available to Langston. Langston reserves the right to charge Client on a time and materials basis in the event that Langston considers that such assistance is onerous, complex, frequent, or time consuming
8.1 Review of Information and Records. Upon Client’s reasonable written request, Langston will make available to Client all information in Langston’s possession reasonably necessary to demonstrate Langston’s compliance with Data Protection Laws and Langston’s obligations set out in this DPA. Such information will be made available to Client no more than once per calendar year and subject to the confidentiality obligations of the Agreement or a mutually agreed non-disclosure agreement.
8.2 Audits. If Client requires information for its compliance with Data Protection Laws in addition to the information provided under Section 8.1, at Client’s sole expense and to the extent Client is unable to access the additional information on its own, Langston will allow for, cooperate with, and contribute to reasonable assessments and audits, including inspections, by Client or an auditor mandated by Client (“Mandated Auditor”), provided that (a) Client provides Langston with reasonable advance written notice including the anticipated date of the audit, the proposed scope of the audit, and the identity of any Mandated Auditor, which shall not be a competitor of Langston; (b) Langston approves the Mandated Auditor in writing, with such approval not to be unreasonably withheld; (c) the audit is conducted during normal business hours and in a manner that does not have any adverse impact on Langston’s normal business operations; (d) Client or any Mandated Auditor complies with Langston’s standard safety, confidentiality, and security policies or procedures in conducting any such audits; (e) any records, data, or information accessed by Client or any Mandated Auditor in the performance of any such audit, or any results of any such audit, will be deemed to be the Confidential Information of Langston and subject to a nondisclosure agreement to be provided by Langston; and (f) Client may initiate such audit not more than once per calendar year unless otherwise required by a Supervisory Authority or Data Protection Laws.
8.3 Results of Audits. Client will promptly notify Langston of any non-compliance discovered during the course of an audit and provide Langston any reports generated in connection with any audit under this Section, unless prohibited by Data Protection Laws or otherwise instructed by a Supervisory Authority. Client may use the audit reports solely for the purposes of meeting Client’s audit requirements under Data Protection Laws to confirm that Langston’s Processing of Client Personal Data complies with this DPA.
9.1 Data Processing Facilities. Langston may, subject to Sections 9.2 and 9.3, Process Client Personal Data in the United States or anywhere Langston or its Subprocessors maintains facilities. Client is responsible for ensuring that its use of the Services complies with any cross-border data transfer restrictions of Data Protection Laws.
9.2 European Transfers. If Client transfers Client Personal Data to Langston that is subject to European Data Protection Laws, and such transfer is not subject to an alternative adequate transfer mechanism under European Data Protection Laws or otherwise exempt from cross-border transfer restrictions, then Client (as “data exporter”) and Langston (as “data importer”) agree that the applicable terms of the Standard Contractual Clauses shall apply to and govern such transfer and are hereby incorporated herein by reference. In furtherance of the foregoing, the parties agree that: (a) the execution of this DPA shall constitute execution of the applicable Standard Contractual Clauses as of the Effective Date of the Agreement; (b) the relevant selections, terms, and modifications set forth in Appendix 3 shall apply, as applicable; and (c) the Standard Contractual Clauses shall automatically terminate once the Client Personal Data transfer governed thereby becomes lawful under European Data Protection Laws in the absence of such Standard Contractual Clauses on any other basis.
9.3 Other Jurisdictions. If Client transfers Client Personal Data to Langston that is subject to Data Protection Laws other than European Data Protection Laws which require the parties to enter into standard contractual clauses to ensure the protection of the transferred Client Personal Data, and the transfer is not subject to an alternative adequate transfer mechanism under Data Protection Laws or otherwise exempt from cross-border transfer restrictions, then the parties agree that the applicable terms of any standard contractual clauses approved or adopted by the relevant Supervisory Authority pursuant to such Data Protection Laws shall automatically apply to such transfer and, where applicable, shall be completed on a mutatis mutandis basis to the completion of the Standard Contractual Clauses as described in Section 9.2.
Following termination or expiration of the Agreement, Langston shall delete Client Personal Data, except as required by applicable law, or, upon Client’s written request (to be provided within thirty (30) days of termination or expiration) and at Client’s cost, return such Client Personal Data in its possession or control and delete existing copies thereof. If Langston retains Client Personal Data pursuant to applicable law, Langston agrees that all such Client Personal Data will continue to be protected in accordance with this DPA.
This DPA will, notwithstanding the expiration or termination of the Agreement, remain in effect until, and automatically expire upon, Langston’s deletion or return of all Client Personal Data. Should any provision of this DPA be invalid or unenforceable, then the remainder of this DPA shall remain valid and in force. The invalid or unenforceable provision shall be either (a) amended as necessary to ensure its validity and enforceability, while preserving the intent of the provision as closely as possible; or, if this is not possible, (b) construed in a manner as if the invalid or unenforceable part had never been contained therein. To the extent of any conflict or inconsistency between this DPA and the other terms of the Agreement in relation to the Processing of Client Personal Data, this DPA will govern. Unless otherwise expressly stated herein, the parties will provide notices under this DPA in accordance with the Agreement, provided that all such notices may be sent via email. Any liabilities arising in respect of this DPA are subject to the limitations of liability under the Agreement. This DPA will be governed by and construed in accordance with the governing law and jurisdiction provisions in the Agreement, unless required otherwise by Data Protection Laws.
1. Subject matter and duration of the Processing of Client Personal Data
The subject matter and duration of the Processing are as described in the Agreement and the DPA.
2. Nature and purpose of the Processing of Client Personal Data
The nature and purpose of the Processing is to perform research (primarily through the use of online surveys) to provide market and customer insights as further described in the Agreement and carrying out the instructions set forth in Section 2.2 of the DPA. Depending on the nature of the Services, the processing activities may include appending pseudonymized Client Material pertaining to its customers to self-reported responses of Client Sourced Research Participants collected through Langston-sourced online surveys, analyzing the combined data, and sharing insights with Client.
3. The categories of Data Subjects to whom Client Personal Data relates
The categories of Data Subjects shall be as is contemplated or related to the Processing described in the Agreement, and may include Client’s current, former, and potential customers.
4. The categories of Client Personal Data
The categories of Client Personal Data Processed are those categories contemplated in and permitted by Agreement, and may include Client’s customer or user IDs and such customers’ or users’ related attributes.
5. The sensitive data included in Client Personal Data
The categories of sensitive Client Personal Data Processed are those categories contemplated in and permitted by the Agreement, and may include personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, data concerning health (including mental or physical health condition or diagnosis), and data concerning a natural person’s sex life or sexual orientation.
The restrictions or safeguards applied to such data are described in Appendix 2.
6. The frequency of Client’s transfer of Client Personal Data to Langston:
If applicable, on a continuous basis for the term of the Agreement.
7. The period for which Client Personal Data will be retained, or, if that is not possible, the criteria used to determine that period:
As set forth in the DPA or the Agreement.
8. For transfers to Subprocessors, the subject matter, nature and duration of the Processing of Client Personal Data:
If applicable, for the same subject matter, nature, and duration set forth above.
1. Information Security Program. Implement, maintain, and comply with information security policies and procedures designed to protect the confidentiality, integrity, and availability of Client Personal Data and any systems that store or otherwise Process it, which are: (a) aligned with an industry-standard control framework (e.g., NIST SP 800-53, ISO 27001, CIS Critical Security Controls); (b) approved by executive management; (c) reviewed and updated at least annually; and (d) communicated to all personnel with access to Client Personal Data.
2. Risk Assessment. Maintain risk assessment procedures for the purposes of periodic review and assessment of risks to the organization, monitoring and maintaining compliance with the organization’s policies and procedures, and reporting the condition of the organization’s information security and compliance to internal senior management.
3. Personnel Training. Train personnel to maintain the confidentiality, integrity, and availability of Client Personal Data, consistent with the terms of the Agreement and Data Protection Laws.
4. Vendor Management. Prior to engaging Subprocessors and other subcontractors, conduct reasonable due diligence and monitoring to ensure subcontractors are capable of maintaining the confidentiality, integrity, and availability of Client Personal Data.
5. Access Controls. Only authorized personnel and third parties are permitted to access Client Personal Data. Maintain logical access controls designed to limit access to Client Personal Data and relevant information systems (e.g., granting access on a need-to-know basis, use of unique IDs and passwords for all users, periodic review and revoking or changing access when employment terminates or changes in job functions occur).
6. Secure User Authentication. Maintain password controls designed to manage and control password strength, expiration, and usage. These controls include prohibiting users from sharing passwords and requiring that passwords controlling access to Client Personal Data must be at least 8 characters in length, meet minimum complexity requirements, and not be stored in readable format on the organization’s computer systems.
7. Incident Detection and Response. Maintain policies and procedures to detect and respond to actual or reasonably suspected Security Incidents, and encourage the reporting of such incidents.
8. Encryption. Apply industry standard encryption to Client Personal Data: (a) stored on any medium (i.e., laptops, mobile devices, portable storage devices, file servers and application databases); and (b) transmitted across any public network (such as the Internet) or wirelessly.
9. Network Security. Implement network security controls such as up-to-date firewalls and layered DMZs designed to protect systems from intrusion and limit the scope of any successful attack.
10. Vulnerability Management. Detect, assess, mitigate, remove, and protect against new and existing security vulnerabilities and threats, including viruses, bots, and other malicious code, by implementing vulnerability management, threat protection technologies, and scheduled monitoring procedures.
11. Change Control. Follow change management procedures and implement tracking mechanisms designed to test, approve, and monitor all changes to the organization’s technology and information assets.
12. Business Continuity and Disaster Recovery. Maintain business continuity and disaster recovery policies and procedures designed to maintain service and recover from foreseeable emergency situations or disasters.
1. Application of Modules. If Client is acting as a Controller with respect to Client Personal Data, “Module Two: Transfer controller to processor” of the Standard Contractual Clauses shall apply. If Client is acting as a Processor to a third-party Controller with respect to Client Personal Data, Langston is a sub-Processor and “Module Three: Transfer processor to processor” of the Standard Contractual Clauses shall apply.
2. Sections I-V. The parties agree to the following selections in Sections I-IV of the Standard Contractual Clauses: (a) the parties select Option 2 in Clause 9(a) and the specified time period shall be the notification time period set forth in Section 5. of the DPA; (b) the optional language in Clause 11(a) is omitted; (c) the parties select Option 1 in Clause 17 and the governing law of the Netherlands will apply; and (d) in Clause 18(b), the parties select the courts of the Netherlands.
3. Annexes. The name, address, contact details, activities relevant to the transfer, and role of the parties set forth in the Agreement and the DPA shall be used to complete Annex I.A. of the Standard Contractual Clauses. The information set forth in Appendix 1 to the DPA shall be used to complete Annex I.B. of the Standard Contractual Clauses. The competent supervisory authority in Annex I.C. of the Standard Contractual Clauses shall be the relevant supervisory authority determined by Clause 13 and the GDPR, unless otherwise set forth in Sections 5 or 6 of this Appendix 3. If such determination is not clear, then the competent supervisory authority shall be the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). The technical and organizational measures in Annex II of the Standard Contractual Clauses shall be the measures set forth in Appendix 2 to the DPA.
4. Supplemental Business-Related Clauses. In accordance with Clause 2 of the Standard Contractual Clauses, the parties wish to supplement the Standard Contractual Clauses with business-related clauses, which shall neither be interpreted nor applied in such a way as to contradict the Standard Contractual Clauses (whether directly or indirectly) or to prejudice the fundamental rights and freedoms of Data Subjects. Langston and Client therefore agree that the applicable terms of the Agreement and the DPA shall apply if, and to the extent that, they are permitted under the Standard Contractual Clauses, including without limitation the following:
5. Transfers from the United Kingdom. If Client transfers Client Personal Data to Langston that is subject to UK Data Protection Laws, the parties acknowledge and agree that: (a) the template addendum issued by the Information Commissioner’s Office of the United Kingdom and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022 (available at: https://ico.org.uk/media/for-organisations/documents/4019539/international-data-transfer-addendum.pdf), as it may be revised from time to time by the Information Commissioner’s Office (the “UK Addendum”) shall be incorporated by reference herein; (b) the UK Addendum shall apply to and modify the Standard Contractual Clauses solely to the extent that UK Data Protection Laws apply to Client’s Processing when making the transfer; (c) the information required to be set forth in “Part 1: Tables” of the UK Addendum shall be completed using the information provided in this Appendix 3 and the DPA; and (d) either party may end the UK Addendum in accordance with section 19 thereof.
6. Transfers from Switzerland. If Client transfers Client Personal Data to Langston that is subject to the Swiss FADP, the following modifications shall apply to the Standard Contractual Clauses to the extent that the Swiss FADP applies to Client’s Processing when making that transfer: (a) the term “member state” as used in the Standard Contractual Clauses shall not be interpreted in such a way as to exclude Data Subjects in Switzerland from suing for their rights in their place of habitual residence in accordance with Clause 18(c) of the Standard Contractual Clauses; (b) references to the GDPR or other governing law contained in the Standard Contractual Clauses shall also be interpreted to include the Swiss FADP; and (c) the parties agree that the supervisory authority as indicated in Annex I.C of the Standard Contractual Clauses shall be the Swiss Federal Data Protection and Information Commissioner.